For the complete documentation index, see llms.txt. This page is also available as Markdown.

A Kubernetes cluster role was created

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

Requires one of the following data sources: AWS Audit Log OR Azure Audit Log OR Gcp Audit Log OR Kubernetes Audit Logs

Detection Modules

Cloud

Detector Tags

Kubernetes - API

ATT&CK Tactic

Persistence (TA0003), Privilege Escalation (TA0004)

ATT&CK Technique

Account Manipulation: Additional Container Cluster Roles (T1098.006)

Severity

Informational

Description

A Kubernetes cluster role was created.

Attacker's Goals

  • Create overpermissive cluster roles to escalate privileges within the Kubernetes cluster.

Investigative actions

  • Check the permissions granted to the newly created Kubernetes cluster role.

  • Check whether this cluster role was bound to an identity via a ClusterRoleBinding or RoleBinding.

  • Verify whether the identity that created the cluster role is authorized to perform RBAC operations.

  • Review subsequent API calls made by the same identity for signs of privilege escalation or lateral movement.

Variations

Administrative Kubernetes cluster role was created for the first time

Synopsis

Field
Value

ATT&CK Tactic

Persistence (TA0003), Privilege Escalation (TA0004)

ATT&CK Technique

Account Manipulation: Additional Container Cluster Roles (T1098.006)

Severity

Medium

Description

A Kubernetes cluster role with administrative permissions was created for the first time by the identity.

Attacker's Goals

  • Create overpermissive cluster roles to escalate privileges within the Kubernetes cluster.

Investigative actions

  • Check the permissions granted to the newly created Kubernetes cluster role.

  • Check whether this cluster role was bound to an identity via a ClusterRoleBinding or RoleBinding.

  • Verify whether the identity that created the cluster role is authorized to perform RBAC operations.

  • Review subsequent API calls made by the same identity for signs of privilege escalation or lateral movement.

A Kubernetes cluster role with administrative permissions was created

Synopsis

Field
Value

ATT&CK Tactic

Persistence (TA0003), Privilege Escalation (TA0004)

ATT&CK Technique

Account Manipulation: Additional Container Cluster Roles (T1098.006)

Severity

Low

Description

A Kubernetes cluster role with administrative permissions was created.

Attacker's Goals

  • Create overpermissive cluster roles to escalate privileges within the Kubernetes cluster.

Investigative actions

  • Check the permissions granted to the newly created Kubernetes cluster role.

  • Check whether this cluster role was bound to an identity via a ClusterRoleBinding or RoleBinding.

  • Verify whether the identity that created the cluster role is authorized to perform RBAC operations.

  • Review subsequent API calls made by the same identity for signs of privilege escalation or lateral movement.

A Kubernetes cluster role was created for the first time by the identity

Synopsis

Field
Value

ATT&CK Tactic

Persistence (TA0003), Privilege Escalation (TA0004)

ATT&CK Technique

Account Manipulation: Additional Container Cluster Roles (T1098.006)

Severity

Low

Description

A Kubernetes cluster role was created for the first time by the identity.

Attacker's Goals

  • Create overpermissive cluster roles to escalate privileges within the Kubernetes cluster.

Investigative actions

  • Check the permissions granted to the newly created Kubernetes cluster role.

  • Check whether this cluster role was bound to an identity via a ClusterRoleBinding or RoleBinding.

  • Verify whether the identity that created the cluster role is authorized to perform RBAC operations.

  • Review subsequent API calls made by the same identity for signs of privilege escalation or lateral movement.

Was this helpful?